Enhanced Lattice-Based Signatures on Reconfigurable Hardware

Enhanced Lattice-Based Signatures on Reconfigurable Hardware
复制标题

DOI:
10.1007/978-3-662-44709-3_20
复制
发表时间:
2014-09
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
T. Pöppelmann;L. Ducas;Tim Güneysu
T. Pöppelmann;L. Ducas;Tim Güneysu
中科院分区:
其他
文献类型:
--
作者:
T. Pöppelmann;L. Ducas;Tim Güneysu

文献摘要

被引文献

相似文献

最近的双峰格签名方案(布利斯)表明,基于格的结构已经发展成为RSA或ECC的实用替代方案。除了具有5600位的相当小的签名以实现128位安全级别外,布利斯还可以在软件中实现极快的签名和签名验证。然而,由于高精度的高斯噪声的复杂采样,目前还不清楚该方案是否可以有效地映射到嵌入式设备。尽管布利斯的作者也提出了一种新的抽样算法使用伯努利变量这种方法是更复杂的比以前的方法使用大型预先计算的表格。使用大型表来实现高性能的明显缺点是,它们不能用于内存有限的受限计算环境(如FPGA)。因此,在这项工作中,我们提出了一个有效的累积分布表(CDT)基于高斯采样器涉及Peikert的卷积引理和Kullback-Leibler发散的可重构硬件技术。基于我们的增强型采样器设计,我们为Xilinx Spartan-6 FPGA提供了第一个布利斯架构,该架构集成了基于快速FFT/NTT的多项式乘法、稀疏乘法和一个哈希函数。此外,我们比较了CDT与伯努利方法,并表明,对于特定的Bliss-I参数集的改进的CDT方法是更快,更低的面积消耗。我们的内核使用2,431个片、7.5个BRAM和6个DSP,平均在126μs内执行签名操作。验证时间甚至更短,只需70μs。
The recent Bimodal Lattice Signature Scheme (Bliss) showed that lattice-based constructions have evolved to practical alternatives to RSA or ECC. Besides reasonably small signatures with 5600 bits for a 128-bit level of security, Bliss enables extremely fast signing and signature verification in software. However, due to the complex sampling of Gaussian noise with high precision, it is not clear whether this scheme can be mapped efficiently to embedded devices. Even though the authors of Bliss also proposed a new sampling algorithm using Bernoulli variables this approach is more complex than previous methods using large precomputed tables. The clear disadvantage of using large tables for high performance is that they cannot be used on constrained computing environments, such as FPGAs, with limited memory. In this work we thus present techniques for an efficient Cumulative Distribution Table (CDT) based Gaussian sampler on reconfigurable hardware involving Peikert’s convolution lemma and the Kullback-Leibler divergence. Based on our enhanced sampler design, we provide a first Bliss architecture for Xilinx Spartan-6 FPGAs that integrates fast FFT/NTT-based polynomial multiplication, sparse multiplication, and a Keccak hash function. Additionally, we compare the CDT with the Bernoulli approach and show that for the particular Bliss-I parameter set the improved CDT approach is faster with lower area consumption. Our core uses 2,431 slices, 7.5 BRAMs, and 6 DSPs and performs a signing operation in 126μs on average. Verification takes even less with 70μs.